Executive brief
Puwell IP cameras used for video surveillance contain a debug interface left enabled in production firmware that allows remote attackers to execute arbitrary system commands without any authentication. An attacker with network access can send specially crafted messages to TCP port 34567 to gain complete control of the camera with root privileges, potentially compromising video feeds, enabling lateral movement into corporate networks, and allowing installation of persistent malware.
Technical details
The vulnerability is a command injection flaw in the binary protocol service running on TCP port 34567 of affected Puwell IP cameras. The DebugShell interface, intended for development and management, remains exposed and active in production firmware. An unauthenticated attacker can send a JSON payload via the proprietary binary protocol with a "DebugShell" command field to invoke arbitrary OS commands. The vulnerable code passes user-supplied command strings directly to the OS without input validation or sanitization, executing them with root privileges. No authentication or session validation is enforced; arbitrary session ID values are accepted. The vulnerability affects firmware versions 2.x through 4.x and can be exploited remotely by any network-adjacent attacker.
Affected products
- Puwell IP Camera 2.x through 4.x
Timeline
- 2026-07-14: disclosed
- 2026-08-04: advisory